Solved

exchange tracking logs recipient empty

Posted on 2014-10-31
6
244 Views
Last Modified: 2014-11-16
I have just been given a set of message tracking logs (from a 2010 exchange server) and this is the first time I have dealt with such logs. The logs seem to be in comma separated format, so I have imported one of the logs into excel to see what information they give you. However one thing I noticed, is the recipient address is always empty in every row of data! Is this normal? The sender address is always populated, but it only seems to be that of internal employees. I was hoping the logs would have information coming into and going out of the organisation, i.e. external email addresses as well. Do these logs not work in that way?
0
Comment
Question by:pma111
  • 3
  • 2
6 Comments
 
LVL 13

Accepted Solution

by:
Andy M earned 500 total points
ID: 40415391
It would depend on how the logs were exported as there's many different switches to include/exclude specific data. In 2010 the message tracking logs can be viewed/searched within the Exchange Management Console itself if you need to double check them.

Tracking logs include everything (external and internal traffic) within them so it sounds like it has been filtered during the export.

This may help in exporting the logs: http://blogs.technet.com/b/exchange/archive/2008/12/01/3406581.aspx
0
 
LVL 3

Author Comment

by:pma111
ID: 40415427
Its weird because the field is there, there are a number of fields included in the reports that dont actually have any data in them. As far as I know the logs were simply copied of the file system, so its not like they could filter them out.
0
 
LVL 16

Expert Comment

by:Rajitha Chimmani
ID: 40416251
Would you copy a sample file here? It all depends on what properties were included while exporting and what was the input command given to extract the logs
0
Complete VMware vSphere® ESX(i) & Hyper-V Backup

Capture your entire system, including the host, with patented disk imaging integrated with VMware VADP / Microsoft VSS and RCT. RTOs is as low as 15 seconds with Acronis Active Restore™. You can enjoy unlimited P2V/V2V migrations from any source (even from a different hypervisor)

 
LVL 13

Expert Comment

by:Andy M
ID: 40418926
I have seen before that the export to csv doesn't always copy the information required, hence I always have a look at Exchange's own tracking log explorer if there appears to be something missing on the csv. If the information is also missing on the tracking log explorer then it would indicate a problem (maybe corruption) on the logs themselves.
0
 
LVL 3

Author Comment

by:pma111
ID: 40419209
No export was done the raw log files were copied from a backup
0
 
LVL 3

Author Comment

by:pma111
ID: 40419212
Confidentiality means unfortunately cant upload a sample
0

Featured Post

Why You Should Analyze Threat Actor TTPs

After years of analyzing threat actor behavior, it’s become clear that at any given time there are specific tactics, techniques, and procedures (TTPs) that are particularly prevalent. By analyzing and understanding these TTPs, you can dramatically enhance your security program.

Join & Write a Comment

Suggested Solutions

Not sure what the best email signature size is? Are you worried about email signature image size? Follow this best practice guide.
Follow this checklist to learn more about the 15 things you should never include in an email signature from personal quotes, animated gifs and out-of-date marketing content.
In this video we show how to create an Address List in Exchange 2013. We show this process by using the Exchange Admin Center. Log into Exchange Admin Center.: First we need to log into the Exchange Admin Center. Navigate to the Organization >> Ad…
This video discusses moving either the default database or any database to a new volume.

746 members asked questions and received personalized solutions in the past 7 days.

Join the community of 500,000 technology professionals and ask your questions.

Join & Ask a Question

Need Help in Real-Time?

Connect with top rated Experts

14 Experts available now in Live!

Get 1:1 Help Now